Title
#general
w

wennan.he

10/27/2022, 6:35 PM
message has been deleted
6:36 PM
may i know is there anyway i can avoid fleet fetching this to present as value of osquery?
s

sharvil

10/27/2022, 6:41 PM
It looks like you are building custom packages..you can customize that by setting the
OSQUERY_VERSION
env variable when building it locally as described here https://osquery.readthedocs.io/en/latest/development/building/#identifying-the-osquery-version
Stefano Bonicatti

Stefano Bonicatti

10/27/2022, 6:41 PM
I’m not sure about that but you can choose the version that osquery has to use when you build it, if you want to do a custom build. In that thread Kathy has pointed you to the CMake option that can be overridden while configuring (OSQUERY_VERSION). So when you do
cmake […]
add
-DOSQUERY_VERSION="<your version>"
6:42 PM
ah 😄
w

wennan.he

10/27/2022, 6:47 PM
but the weird thing is this is the pkg i built by debian flow, and you can see the package info. FVFHP07CQ05Q😄ownloads bytedance$ dpkg --info osquery_5.4.0_amd64.deb new Debian package, version 2.0. size 12923020 bytes: control archive=6988 bytes. 43 bytes, 2 lines conffiles 221 bytes, 10 lines control 19298 bytes, 241 lines md5sums 583 bytes, 23 lines * postinst #!/bin/sh Package: osquery Version: 5.4.0 Architecture: amd64 Maintainer: wennan.he Installed-Size: 51166 Depends: sudo, wget Section: admin Priority: extra Homepage:XXX Description: osquery agent you can see the version is 5.4.0. but the present one is another val in fleet.
Stefano Bonicatti

Stefano Bonicatti

10/27/2022, 6:48 PM
Yeah I think the wiki has to be updated, there are 2 versions involved, one is for the binary itself and it’s hardcoded into it. That one is provided via cmake and can be seen either via
osqueryd --version
or querying the
osquery_info
table
6:50 PM
Then you have the version the package, which is passed via
OSQUERY_PACKAGE_VERSION
as a cmake flag too but when building the
osquery-packaging
repo
6:50 PM
I’m not too sure why we have
OSQUERY_VERSION
as an env var
6:51 PM
because it’s not read from there
6:52 PM
ah, sorry, it’s that one has to read the whole process; the env var is just there so that later you can do:
cmake -DCMAKE_BUILD_TYPE=RelWithDebInfo \
  -DCPACK_GENERATOR=DEB \
  -DOSQUERY_PACKAGE_VERSION=${OSQUERY_VERSION} \
  -DOSQUERY_DATA_PATH=${DESTDIR} \
  -DOSQUERY_SOURCE_DIRECTORY_LIST="osquery-src-path;osquery-build-path" \
  ../osquery-packaging
6:52 PM
but otherwise everything is given via CMake options
w

wennan.he

10/27/2022, 6:53 PM
so you mean if i run cmake -DOSQUERY_PACKAGE_VERSION=${OSQUERY_VERSION} is also working? and i will see OSQUERY_VERSION i setup in fleet page?
Stefano Bonicatti

Stefano Bonicatti

10/27/2022, 6:55 PM
That is for the package version itself, Fleet will ignore that because at that point osquery is already installed. What Fleet is picking up is the version hardcoded in the osquery binary, that has to be passed via
OSQUERY_VERSION
but as a CMake flag in the osquery binary configuration process and build
w

wennan.he

10/27/2022, 7:22 PM
OK, thank you for explain, and is there any way i can setup that osquery_version?
Stefano Bonicatti

Stefano Bonicatti

10/27/2022, 7:25 PM
Yes, as I was mentioning here https://osquery.slack.com/archives/C08V7KTJB/p1666896117837239?thread_ts=1666895723.863199&amp;cid=C08V7KTJB you have to pass that as a CMake flag when you are configuring and building osquery
w

wennan.he

10/27/2022, 7:25 PM
ok gotta, thx.
10:53 PM
i tried but right now the val os osquery of my new built package is still 5.4.0-dirty, looks like "-dirty" means there is commit checked in after last commit of my tag, even i tried to move the tag to cover all my commits, it still doesn't work. any suggestion?
10:54 PM
Stefano Bonicatti

Stefano Bonicatti

10/28/2022, 10:04 AM
How have you provided the version to the build?
10:08 AM
Because if you use the cmake flag
OSQUERY_VERSION
, then that will override the version with what you’ve passed, so unless somehow you passed that
-dirty
after the version number, it means to me that you haven’t used
OSQUERY_VERSION
? If you don’t pass it, then
git describe --tags --always --dirty
is what gets used internally. You might want to check again Kathy answer https://osquery.slack.com/archives/C01DXJL16D8/p1666895235514769?thread_ts=1666829283.151999&amp;cid=C01DXJL16D8
10:10 AM
Dirty doesn’t mean that you have a commit after the tag, but that you have changes not staged for commit in your working dir
10:11 AM
So file changes that have not been committed. You might want to check your source folder with
git status
w

wennan.he

10/28/2022, 4:36 PM
you have changes not staged for commit in your working dir what does it mean?
4:36 PM
i really have some commits
4:37 PM
this is my git log
4:37 PM
you can see my commit after the last commit of 5.4.0
Stefano Bonicatti

Stefano Bonicatti

10/28/2022, 4:39 PM
That’s not how it works. The tag is on the top commit (the last), so
git describe […]
it’s correctly taking 5.4.0; but you don’t have to look there. You have to look at
git status
. When you make a change to a file and not do
git add
to it or fully commit it, that in git parlance is a
change not staged for commit
, or another way to say it is that you have your working tree dirty/not clean
4:42 PM
That again means that what you’re building is not actually the state the code would have if you cloned the source code at your tag; there’s some other modification in your source folder which is not tracked
w

wennan.he

10/28/2022, 4:44 PM
i don't add any change when building osquery but i would generate some temp folders to store all the generated files by build itself. So you mean that is the not staged change?
Stefano Bonicatti

Stefano Bonicatti

10/28/2022, 4:45 PM
Have you checked what
git status
gives?
w

wennan.he

10/28/2022, 4:48 PM
i will check it
4:55 PM
thx 4 explain.
5:36 PM
by the official doc, i will create a folder of build to store these tmp files, would this cause that suffix of dirty?
s

sharvil

10/28/2022, 5:38 PM
build
directory will not cause an issue because that's part of
.gitignore
so it gets ignored
w

wennan.he

11/01/2022, 9:23 PM
And could anyone help to explain where did the middle part of the name come from?
Stefano Bonicatti

Stefano Bonicatti

11/01/2022, 9:25 PM
do you mean the
gcede[..]
part? that always comes from
git describe --always --tags --dirty
, but more specifically is the short form of the SHA of the commit the binary has been built from
9:25 PM
you can also obtain it with
git rev-parse --short HEAD
9:27 PM
And it shows because you’re not on a tag
w

wennan.he

11/01/2022, 9:48 PM
thx, i am trying to figure out that how to make it align with pervious name like 5.4.0